CVE-2018-12698
Summary
| CVE | CVE-2018-12698 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-23 23:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM) during the "Create an array for saving the template argument values" XNEWVEC call. This can occur during execution of objdump. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 16.04.4 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 16.04.4 | All | All | All |
| Application | Gnu | Binutils | 2.30 | All | All | All |
| Application | Gnu | Binutils | 2.30 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| USN-4326-1: libiberty vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| Binutils: Multiple vulnerabilities (GLSA 201908-01) — Gentoo security | GENTOO | security.gentoo.org | |
| 85454 – Multiple memory corruptions in objdump / C++ name demangler (binuitils-2.30-15ubuntu1) | MISC | gcc.gnu.org | Exploit, Issue Tracking, Vendor Advisory |
| 23057 – Multiple memory corruptions in objdump (binuitils-2.30-15ubuntu1) | MISC | sourceware.org | Exploit, Issue Tracking, Third Party Advisory |
| USN-4336-1: GNU binutils vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| Bug #1763102 “Multiple memory corruptions in objdump (binuitils-...” : Bugs : binutils package : Ubuntu | MISC | bugs.launchpad.net | Exploit, Third Party Advisory |
| GNU libiberty CVE-2018-12698 Memory Corruption Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710158 Gentoo Linux Binutils Multiple vulnerabilities (GLSA 201908-01)